VYPR
Medium severity4.8NVD Advisory· Published Nov 4, 2018· Updated Jun 17, 2026

CVE-2018-18927

CVE-2018-18927

Description

An issue was discovered in PublicCMS V4.0. It allows XSS by modifying the page_list "attached" attribute (which typically has 'class="icon-globe icon-large"' in its value), as demonstrated by an 'UPDATE sys_module SET attached = "[XSS]" WHERE id="page_list"' statement.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • Range: = 4.0.0
  • cpe:2.3:a:publiccms:publiccms:4.0:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:publiccms:publiccms:4.0:*:*:*:*:*:*:*
    • (no CPE)range: 4.0

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.